Description
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
Published: 2026-07-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is improper access control (CWE‑284) in the Windows DNS client that permits an authorized user to tamper with DNS client settings locally. The description indicates that such tampering could alter the client configuration or behavior on the infected machine, potentially compromising the integrity of DNS resolution on that host.

Affected Systems

Affected systems include Microsoft Windows 11 version 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 (including Server Core installations).

Risk and Exploitability

The CVSS score of 7.1 places the vulnerability in the moderate severity range. The EPSS score of less than 1 % indicates a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker must have authorized user privileges on a target device to modify DNS configuration, which could affect the confidentiality, integrity, and availability of DNS resolution for that host.

Generated by OpenCVE AI on August 1, 2026 at 09:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses CVE‑2026‑50465.
  • Restrict local administrative privileges to users who truly need them.
  • Configure the DNS client to be read‑only through Group Policy or local security policy, preventing tampering.
  • Enable auditing of DNS client configuration changes and review logs regularly for suspicious activity.

Generated by OpenCVE AI on August 1, 2026 at 09:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
Title Windows DNS Client Tampering Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-284
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:24:57.557Z

Reserved: 2026-06-04T18:59:17.978Z

Link: CVE-2026-50465

cve-icon Vulnrichment

Updated: 2026-07-16T13:46:15.459Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:45:03Z

Weaknesses